• After 15+ years, we've made a big change: Android Forums is now Early Bird Club. Learn more here.

How I fixed the Exchange Activesync failed to create account error

Thanks a lot Technocrat for the fix... worked like magic for me. It worked on my HTC desire and on an iPhone of a friend of mines.
 
I tested everything, but the only solution worked for me it was so simple:
The only thing I had to to is to disable the Forms Based Authentication check box !!
 
Which permission isn't propagating that needs to?

This solution worked perfectly for me with a Desire Z connecting to a reverse proxied Exchange 2010 (self signed ssl)

I don't think the issue is with a missing permission, more a corrupt ACL.

I checked the permissions on my mailbox against another domain admin and a standard user they were identical, I ticked the permission inheritance, disabled Activesync on my account then tried to connect to ensure I received a failure, then re-enabled AS and connected again, now working perfectly!
 
Hi I was wondering if anybody had actually got to the botom of this?

I don't really want to universally inherit permission's as this could be a security breach.

Which permission is 'missing' so I can add it?
 
This is how I fixed this problem:

1.Start Internet Information Services (IIS) Manager (in Administrative Tools)
2.Under Websites, Default Website, select exchange-oma.
3.Right-click exchange-oma. Click Properties.
4.Click the Directory Security tab.
5.Under Authentication and access control, click Edit.
6.Make sure that only the following authentication methods are enabled, and then click OK:
•Integrated Windows authentication
•Basic authentication
7.On the Directory Security tab, under IP address and domain name restrictions, click Edit.
8.Click the option for Denied access, click Add, click Single computer and type the local IP address of your server that you are configuring (e.g., 192.168.XXX.XXX), and then click OK twice. Also add: 127.0.0.1
9.Under Secure communications, click Edit. Make sure that Require secure channel (SSL) is NOT enabled, and then click OK.
10.Click OK, and then close the IIS Manager.
11.Restart the IIS Admin service. To do this, follow these steps:
•Click Start, click Run, type services.msc, and then click OK.
•In the list of services, right-click IIS Admin service, and then click Restart

Source: http://support.microsoft.com/kb/817379
Note: I did NOT have to do all the steps in this KB article!
For example, SBS2003 should already have exchange-oma
and I did NOT have to disable Forms-based Authentication.

Note: This may also fix the problem on SBS2003:
Server Managment, Internet & Email, Connect to the Internet, use wizard leaving all at current settings except make sure Outlook Web Access and Outlook Mobile Access are checked and complete the wizard.

Keywords: activesync android "failed to create the account" "failed to connect"
Article ID: 817379 - Exchange ActiveSync and Outlook Mobile Access errors occur when SSL or forms-based authentication is required for Exchange Server 2003
 
Want to thank Technocrat for his solution. Worked perfectly for my HTC One X. Had one out of 3 exchange accounts working but now I have 3 out of 3 exchange accounts working :)
 
I registered on this site especially to add my thanks and gratitude for this fix. It solved my issue which has had me frustrated since my new Galaxy S4 arrived a week ago.

  • I am a domain admin. Mail server runs Exchange 2010. Self-signed SSL certificate.
  • Galaxy S4, unrooted, stock ROM (Jellybean 4.2.2)
  • Security pop-up would not appear, could not sync with Exchange at all despite could contact mail server.
  • Inherited parent permissions on my AD account object as described above. Did not touch OU.
  • Security pop-up appeared. Accepted, synched once, worked.
  • Unticked "Inherit permissions" box, reverted changes. Still works.
Annoyingly, exchange sync works fine for normal users in the network. It's specfically administrators that have this issue. It's going to be because the administrator OU doesn't inherit permissions or GPOs from the top level.

I'd be very interested to know which permission it is exactly. There were a large number of "Exchange Server" entries and not knowing which it was (and what special permission it required) I chose not to try to edit anything individually.

My thanks again for this solution. Two major headaches fixed today, this was one of them and it's a great relief.
 
Back
Top Bottom